Data Diode

Packet forwarding

Can be achieved by modifying /etc/sysctl.conf


and then running sudo sysctl -p

For the forwarding rules:

iptables -t nat -A PREROUTING -i $interface -p udp --dport $input_port -j DNAT --to $destination:$output_port
iptables -t nat -A POSTROUTING -o $interface -j MASQUERADE


Far End Fault (FEF)

Far End Fault (FEF) is a part of the IEEE 802.3u standard (Fast Ethernet). When a media converter stops receiving a signal, it will stop emiting as wel , thus bringing the connection down in both directions.

This is not desirable for a data diode.

This mechanism is implemented by most modern media converters. However, some media converters have a dip switch that allows to turn this feature off:

According to some sources, this function may also be auto-disabled when different media converters are used:

